Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Latest bugs in LastPass allowed attackers to steal passwords

Add as a preferred source on Google

Password manager LastPass is patching a number of critical vulnerabilities in its software that left users’ passwords potentially leaking.

No software is ever totally safe and while password managers can offer a degree of security and convenience, they are not impervious as these security flaws demonstrate.

Recommended Videos

The latest bugs were discovered by Google Project Zero researcher Tavis Ormandy, who is renown for finding and disclosing flaws in security software. Ormandy said he found a vulnerability that allows for the stealing of passwords by running a binary version of the password manager’s extension.

In a proof of concept, Ormandy demonstrated using the code to launch an application. He opened the calculator in Windows but, he said, a malicious actor could use this code to steal password details when the manager is entering them into the login fields.

“That doesn’t look good, this script will proxy unauthenticated window messages to the extension. This is clearly a mistake, because anybody can do [it],” he wrote in his advisory.

“Therefore, this allows complete access to internal privileged LastPass RPC [remote procedure calls] commands,” he said.

https://twitter.com/taviso/status/844312124541186048

LastPass said in a tweet that this has been fixed and promised a blog post with more details on what went wrong but the post has yet to materialize.

Ormandy also found remote code execution vulnerabilities in the password manager’s Chrome and Firefox extensions. The Chrome bug has since been patched but the Firefox version remains unpatched for now but this may be due to a hold up on Mozilla’s end.

“We are aware of reports of a Firefox add-on vulnerability. Our security is investigating and working on issuing a fix,” said LastPass on Tuesday night.

This isn’t the first time that Ormandy has poked holes in LastPass’ software. In 2016, he disclosed a Firefox-related flaw that would have allowed an attacker to access someone’s extension, without them knowing, and delete the passwords.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
You won’t believe it, but Motorola actually makes a terrific head-turner of a laptop
Motorola’s Moto Book 60 Pro is surprisingly stylish, and the pricing makes it even better
Moto Book 60 Pro in PANTONE Bronze Green

Motorola is not the name I expect to see on a genuinely good laptop. A stylish phone? Sure. A foldable with some personality? Absolutely. But a thin-and-light notebook that actually feels well judged on both design and value was a genuine surprise. And yet, the Moto Book 60 Pro is one of the more quietly impressive laptops in its segment.

With the broader laptop market being in a mess, Motorola's laptops feel refreshing. It is capable, attractive, and still approachable at a time when pricing elsewhere has become increasingly rough.

Read more
Zoom will now check if you are a human or an AI imposter during video meetings
Biometric badges, iris scans, and AI bouncers: welcome to the future of your Monday morning standup.
Zoom face scan technology.

Zoom video calls just got a new kind of awkward small feature. The platform will now ask you whether you’re human. It has partnered with World, Sam Altman’s iris-scanning identity company (previously known as Worldcoin), to add real-time human verification inside meetings. 

The feature, launched on April 17, 2026, is a part of World’s ID 4.0 rollout. It lets hosts confirm that every face on the call belongs to a real person, not an AI-generated imposter. 

Read more
All Gemini users can now access Notebook projects on the web without paying a dime
Gemini Notebooks are free now and they work with NotebookLM too
gemini-notebooklm

Google just made one of Gemini's most useful features available to everyone. The Notebooks feature, initially rolled out to paid AI subscribers earlier this month, is now available to all free users on the web. If you use Gemini regularly, this is a pretty big deal.

https://twitter.com/NotebookLM/status/2045172109073404312

Read more